CMMC
The Department of Defense certification requirement now flowing down through defense contracts.
What it is
CMMC verifies implementation of NIST SP 800-171 controls by contractors handling controlled unclassified information. Level 1 covers federal contract information and is self-assessed; Level 2 covers CUI across 110 controls and generally requires assessment by an authorized C3PAO; Level 3 adds requirements assessed by the government. Contract clauses determine which level applies, and the requirement flows down to subcontractors.
Who typically needs it
- Defense manufacturers and suppliers with CUI in scope under DFARS clauses
- Subcontractors receiving flow-down requirements from a prime
- Companies with an SPRS score submitted years ago that no longer reflects reality
- Organizations bidding on contracts with a CMMC requirement in the solicitation
- Automotive-adjacent defense suppliers who also carry a TISAX obligation
What the engagement looks like
Framewise partners with an authorized C3PAO for the formal Level 2 assessment. We handle readiness, implementation, and audit preparation; the assessment itself is performed by the C3PAO, and we do not hold C3PAO status. Keeping those roles separate is a requirement of the program, not a preference.
Baseline. We assess against all 110 controls, calculate the SPRS score, and identify the CUI boundary. Boundary definition drives cost more than any other decision in this framework.
Build. We author the System Security Plan, the Plan of Action and Milestones, the Shared Responsibility Matrix for your cloud and managed service providers, and the full policy suite. We work through remediation with your IT team or MSP directly.
Audit Sprint. We run a mock assessment against the CMMC assessment guide, close remaining findings, and support you through the C3PAO engagement — evidence packaging, interview preparation, and findings response.
Steady State. Certification runs three years with annual affirmation. We maintain the SSP and POA&M, keep evidence current, and manage the affirmation cycle so the recertification is not a second full program.
Common failure modes
- A CUI boundary drawn around the whole company rather than the enclave that handles it
- An SPRS score self-reported optimistically and never revisited
- MSP responsibilities assumed rather than documented in a Shared Responsibility Matrix
- POA&M items left open past the allowed closeout window
Price range
Programs typically run between $54,000 and $66,000 for the Level 2 Build phase, plus third-party assessment costs paid directly to the C3PAO.
Talk to us about your CMMC.
Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.
Book a consultation